Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Omer Levi Hevroni — K8s can keep a secret?

37 min1 maj 2019

Om avsnittet

Putting an application in Kubernetes does not solve the problem of getting secrets to it safely. Omer Levi Hevroni, a developer and security champion, explains the risks that led his team to create Kamus. He starts with Kubernetes basics and the broader responsibilities of developers who own applications through deployment and operation. The discussion then follows secrets from source control into the cluster, comparing native mechanisms with encryption and external key-management options. Omer walks through the Kamus workflow, including how an encrypted secret is tied to the application allowed to decrypt it. He also discusses the threats the design addresses and the value of documenting assumptions. This archive conversation captures a practical approach to secrets management and its tradeoffs.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Omer Levi Hevroni:
Omer Levi Hevroni on GitHub

Mentioned in this episode:
Kamus — historical project repository
Kubernetes
Azure Key Vault

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Can Kubernetes keep a secret?
02:38 From developer to security champion
04:16 Learning to code and owning applications
06:32 Kubernetes basics
08:44 The challenge of handling application secrets
10:34 Developers responsible for the whole lifecycle
11:19 Keeping secrets usable and controlled
14:18 Secrets accidentally committed to source code
17:09 Options for secrets in Kubernetes
18:58 Recovery and consuming secrets in application code
21:08 Encryption and external key management
24:22 Why the team built Kamus
26:42 The Kamus encryption and decryption workflow
28:21 Where encrypted secrets and keys live
31:43 Threats addressed by the design
34:22 Documentation, threat model, and further resources

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.